Privacy policy
Are they listening?, by Headway Tech LLC. Last updated October 8, 2026.
The short version. There's no account, no advertising and no analytics. Detection happens on your phone. Three things leave it, each only when you use that feature: the VPN carries your traffic through our server, which keeps no logs; the email leak check sends the address you type to Have I Been Pwned; and the lists the app downloads (scam numbers, ad and scam sites, satellite orbits, the road map) are the same public files for everyone. Nothing about your texts, calls, browsing, scans or location is sent to us.
What the app does on your phone
Are they listening? looks for devices near you that can hear, see or track you, and explains what each one does. It listens to what devices broadcast on their own over Bluetooth, briefly connects to Bluetooth devices it can't name to read what they call themselves, and asks devices on the Wi-Fi you have joined to identify themselves. It doesn't pair with, record from or take control of anything it finds. The one thing it ever sends a device is a ring command, and only when you tap Make it beep on a tracker that may be following you.
What we collect
Nothing, unless you turn on the VPN: Headway Tech LLC does not collect or receive personal information, and we can't see your scans, your location, your routes, your texts, your calls, the sites you visit or the devices around you. What the VPN keeps is listed below, and it isn't about what you do. The outside services a feature asks, and exactly what each receives, are in the table further down.
The VPN
The VPN is off until you turn it on. When it's on, your iPhone's internet traffic goes, encrypted, from your iPhone to our server, run by Headway Tech LLC at OVHcloud in Oregon, USA, and from there to the internet. The Wi-Fi you're on sees only that you're connected to our server, not the sites and apps you use.
What our server keeps, for each iPhone that turns it on: a random ID, a hashed copy of a token only that iPhone holds (so only it can change or remove its record), whether it blocks ads and trackers, the day it was added, and its VPN key so it can connect. That's all. We use it only to run the VPN, and we don't sell it, use it for any other purpose, or disclose it to anyone else.
What it doesn't keep: the sites or apps you use, your traffic, your DNS lookups, your IP address, or when you connect and disconnect. The VPN service, the DNS resolver, the firewall and the web server on it are set up to write none of this, and we check that they don't. While you're connected, the server holds in memory only what it needs to send your traffic back to you; it's gone when you disconnect.
Blocking: its DNS resolver blocks known malware, phishing and scam sites for everyone, and ads and trackers unless you turn that off, using HaGeZi's public blocklists. It doesn't record what it blocks.
Who else is involved: OVHcloud runs the data center and network our server is in, and carries traffic to and from it as any internet provider does. The server's name, vpn-west.headwaytech.app, is published through Cloudflare's DNS.
Removing it: Remove the VPN from this iPhone (VPN, Details) deletes its key from your iPhone and its record from our server. Deleting the app also takes the VPN off your iPhone.
Legal requests: we answer valid legal process as the law requires. Because the server keeps no logs, we generally have nothing about your activity to give.
What it isn't: it hides your activity from the Wi-Fi network, not from sites you sign in to, and it doesn't make you anonymous. It can't stop cameras or microphones in a room; the scan is for those.
Scams, calls, texts and Safari
Web Protection and the Ad Blocker are Safari content blockers. Safari does the blocking itself from a list the app gives it; the app never sees which pages you open, and neither does Safari tell it. The lists are built from public sources (named in the app under What it can and can't see) and downloaded from our site; the download carries nothing about you.
Call protection is an iOS call directory: the app hands iOS a list of numbers reported to the FTC's Do Not Call registry, and iOS labels or, if you chose, blocks calls from them. The app never sees your calls or your contacts. The list is downloaded from our site once a day.
The text filter runs inside iOS on your phone, on texts from numbers not in your contacts. Nothing from a text leaves the phone. iOS doesn't tell the app whether the filter is on; the app remembers only what you told it.
Is this text a scam? reads the text you paste, or the screenshot you pick, on the phone. The screenshot's text is read by iOS on the phone, and nothing is saved. On an iPhone with Apple Intelligence, Apple's on-device model reads it too, on the phone. A sender's number is checked against the FTC list on the phone. "Report to your carrier" opens a text to 7726 for you to send; "Report to the FTC" opens the FTC's site.
Was your email leaked? sends the address you type to our server, which passes it to Have I Been Pwned with our key and passes the answer back. Neither keeps the address or logs the request. Have I Been Pwned sees the address, as that is the check. If you keep the address, it stays on your phone and the check runs again weekly.
Was a password leaked? sends only the first five characters of a scrambled version of the password to Have I Been Pwned, which answers with every scrambled password that starts the same way. The password itself never leaves the phone.
Outside services, and what each one receives
These are used only when you use the feature named, and only for that feature.
| Service | When | What it receives |
|---|---|---|
| Apple Maps | Any map in the app; searching for a place in Plate readers or drive mode, as you type; planning a route | The area of the map on screen, what you type as you type it, and the start and destination of a route, as in Apple's own Maps app. Governed by Apple's privacy policy. |
| adsb.lol | Overhead, while that screen is open | Your location rounded to about 1 km (0.6 mi), every 20 seconds, to get the aircraft nearby, and for a wider circle every few minutes (every 15 seconds while the sky camera is open) for the GPS check and the camera view. |
| Satellite orbit lists (sky.headwaytech.app, served by Cloudflare; CelesTrak if ours doesn't answer) | Overhead, once a place is set, at most twice a day | Nothing about you: it's the same public file for everyone, and your IP address as with any internet request. Which satellites and planets are over you is worked out on the phone; your location isn't sent. We keep no record of downloads. |
| OpenStreetMap (Nominatim) | Overhead, when you type a place | The place or address you typed. |
| OpenStreetMap (Overpass) | Plate readers, when you tap "Check the live map" | The location being checked, once. The plate reader map is otherwise built into the app, so looking up readers near you doesn't leave the phone. |
| Our road map (roads.headwaytech.app, served by Cloudflare) | Plate readers: when the map first opens near you, and when a route goes through an area the phone doesn't have yet | Which squares of the road map the phone needs, each about 28 by 21 km (17 by 13 mi), and your IP address as with any internet request. Never your start, destination or route: routes past no plate readers are worked out on the phone. We keep no record of downloads. |
| Cloudflare speed test (speed.cloudflare.com) | Who's on my Wi-Fi, Internet: when you tap Run speed test | Test data downloaded and uploaded (up to about 200 MB), and your IP address as with any internet request, which it uses to name your provider and city. Nothing else. |
| Cloudflare (1.1.1.1) and Shodan InternetDB (internetdb.shodan.io) | Who's on my Wi-Fi, Security: when you tap Check what's exposed | Cloudflare is asked for this connection's internet address, and that address is looked up in Shodan's InternetDB, a public record of what its scans of the internet found open there. Nothing else. |
| Public DNS services: Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9) | Who's on my Wi-Fi, Internet: when you tap Compare DNS speed. DNS lookup in Tools asks Cloudflare only when the app doesn't know your router | Lookups of five well-known names (apple.com, google.com, wikipedia.org, amazon.com and cloudflare.com), or the name you typed into DNS lookup, and your IP address, as with any DNS lookup. |
| Have I Been Pwned, through our server (headwaytech.app, served by Cloudflare) | Was your email leaked?: when you check an address, and weekly for an address you keep | The email address, passed on once and not kept by us. Have I Been Pwned's own policy covers what it does with it. |
| Have I Been Pwned | Was a password leaked?: when you check a password | The first five characters of the password's hash. Never the password. |
| Our lists (headwaytech.app, served by Cloudflare) | Scam numbers, once a day; the ad and tracker list, once a week; the Safari self-test page when you open it | Nothing about you: the same public files for everyone, and your IP address as with any internet request. |
| Quad9 (dns.quad9.net, a Swiss nonprofit resolver) | Block in every app, while it is on (from app 1.11.0) | The names of the sites your apps look up, encrypted on the way, the way your internet provider's resolver sees them otherwise. Blocked names never leave the phone. Nothing is sent to us; the filter runs on the phone and keeps two counts there (lookups checked, lookups blocked), no names. Quad9's own policy says it keeps no logs of who asked. |
| Apple (on this phone) | Is this text a scam?, on an iPhone with Apple Intelligence | Nothing leaves the phone: Apple's on-device model runs here. Apple's own Apple Intelligence terms apply. |
| RevenueCat | When the app starts, to check whether you own the unlock or a plan for it and get the prices, and when you buy, restore or manage it | An anonymous purchase ID, the purchase record from Apple, and the device model and app version. No name or email. |
| Expo | When the app checks for an update | The app version and platform, and your IP address as with any internet request. |
| Waze, Google Maps, Apple Maps | When you choose "Open in" one of them on the plate-reader map | The destination you picked, and for a route past fewer cameras a few points along it, are passed to that app, which then works under its own policy. |
The live map check goes to one of three public Overpass servers: overpass-api.de, overpass.kumi.systems or overpass.private.coffee.
Links you open to other sites, such as an aircraft's flight track, the FAA registry or DeFlock, open in your browser under those sites' policies.
Permissions, and why
- Bluetooth: to notice nearby glasses, recorders, trackers, skimmer parts and drones by what they broadcast, to ask the ones it can't name what they are, over a brief read-only connection, and to make a found tracker beep when you ask it to.
- Local Network: to ask devices on the Wi-Fi you have joined what they are, and for the Wi-Fi tools you run: ping, open ports, Wake on LAN and DNS lookup. When you open the app on a Wi-Fi you have scanned before, it checks that Wi-Fi again, at most every half hour, so My Wi-Fi can show what joined since you last looked. The router check compares your router's model with a list built into the app (from CISA's Known Exploited Vulnerabilities catalog); nothing about your router is sent anywhere.
- Location: for Plate readers, Overhead and drive mode, and to show the name of the Wi-Fi you're on (iOS shares it only with apps allowed location). If you have allowed it, a sweep also notes roughly where it happened, to about 1 km, kept only on the phone (see below). Drive mode can keep warning you with the screen off or another app in front; iOS shows the location indicator whenever it does, and it stops when you end the drive.
- Camera: for the Lens finder and Infrared check, which use the live camera view, and for the sky camera in Overhead, which shows the sky behind the names of what's up there. No photos or video are taken or saved.
- Motion sensors and compass: for the sky camera, to work out where the phone is pointing. Read on the phone, used at once and not kept.
- Photos: for the scam check, only the screenshot you pick, read on the phone and not kept. The app never sees the rest of your library.
- Notifications: for drive alerts while another app is in front, for space station reminders you ask for in Overhead, for the spyware check when its file is ready, and for a new leak of an email address you keep.
What stays on your phone
The app keeps only what you would want to find again, only on the phone, and deletes it on these schedules:
- Devices you mark as yours, until you clear them.
- Wi-Fi networks you scan with My Wi-Fi: the devices each one has had, when each was first and last seen, when a device that stays put (a camera, a TV) came back after a while away, when any device changed address, and the names, rooms, notes and "yours or not" answers you give them, until you clear them. Up to 20 networks. Phones and laptops get no come-and-go history, only when each was first and last seen.
- Your last 20 speed tests, the last check of what the internet can see at your address, and the last DNS comparison, until you clear them.
- A log of your sweeps, the last 100.
- Trackers seen in sweeps, for 7 days, so one that keeps turning up can be flagged.
- Rough places where a tracker or wearable was seen, for 30 days, so one that follows you from place to place can be flagged.
- The sky log and the drive log, for 30 days.
- A copy of the public satellite orbit lists, replaced twice a day while you use Overhead, so it works without a signal for a week.
- Spots you report as unmapped plate readers, your answers to "Still there?" on a mapped camera, your last few searches, the places you save, such as Home and Work (where you stood, or the words you searched), and the detour points that took a route past fewer plate readers, so the same trip finds the same road again, until you clear them.
- The road map for the areas your routes go through (data by OpenStreetMap contributors), up to about 200 MB, least used first out, until you clear it.
- Your last scan's phone checks (the rows on Home), the email address you keep for the weekly leak check and its last answer, your "I turned it on" for the text filter, the FTC number list the call directory uses, and the Safari blocker lists, until you forget them or delete the app.
- Your settings, and the last error message if the app hit a bug.
"Forget everything" in Settings clears all of it at once, the kept email address included, except the devices you marked as yours, your settings and the last error message, which each have their own place in Settings. Deleting the app removes everything.
Sharing
When you share a report, a log or a spot, the app hands it to your phone's share sheet. Where it goes from there is your choice; the app never sends it anywhere itself.
Children
The app isn't directed at children under 13, and we don't knowingly collect personal information from them.
This website
headwaytech.app counts its visitors with Cloudflare Web Analytics, which sets no cookies and doesn't follow you across sites. We see totals only, such as page views and the countries they came from. The app itself has no analytics.
Changes
If this policy changes, the new version will be posted here with a new date.
Contact
Headway Tech LLC · [email protected]